CVE-2011-3792: Infoleak
Published Sep 24, 2011
·Updated
Pixelpost 1.7.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by includes/functionsfeeds.php and certain other files.
Affected Software
1 affected component
Pixelpost=1.7.3
Event History
Sep 24, 2011
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-3792?
CVE-2011-3792 is considered to have a moderate severity as it allows attackers to obtain sensitive information.
2
How do I fix CVE-2011-3792?
To fix CVE-2011-3792, update Pixelpost to the latest version where the vulnerability has been addressed.
3
What types of files are affected by CVE-2011-3792?
CVE-2011-3792 specifically affects .php files, including includes/functions_feeds.php.
4
What information can be exposed through CVE-2011-3792?
CVE-2011-3792 can expose the installation path of the Pixelpost application in error messages.
5
Who is affected by CVE-2011-3792?
CVE-2011-3792 affects users of Pixelpost version 1.7.3.